Event ID - 29559

Port No29559
Service NameVagr Nocker
RFC Doc0
ProtocolTCP
DescriptionThe remote host appears to be infected with the Backdoor.VagrNocker trojan. This trojan allows remote access to your system via port 12884 and 21554.
Reference LinkMore Information
AttackName:Vagr Nocker

How To Remove:
1. Click Start, and then click Run. (The Run dialog box appears.)
2. Type regedit, and then click OK. (The Registry Editor opens.)
3. Navigate to the key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
4. In the right pane, delete the value:
BIOSAdapter
C:\WINDOWS\WinBIOS.exe /nosplash
5. Navigate to the key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
6. In the right pane, delete the value:
Windll.exe
C:\WINDOWS\Windll.exe
7. Exit the Registry Editor.

Catch threats immediately

We work side-by-side with you to rapidly detect cyberthreats
and thwart attacks before they cause damage.

See what we caught

Did this information help you to resolve the problem?

Yes: My problem was resolved.
No: The information was not helpful / Partially helpful.